New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 684435 link

Starred by 1 user

Issue metadata

Status: Started
Owner:
Buried. Ping if important.
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: 3
Type: Bug

Blocking:
issue 680418



Sign in to add a comment

Experiment with blocking more parser-inserted script.

Project Member Reported by mkwst@chromium.org, Jan 24 2017

Issue description

aaj@ suggests that we might consider something that would "prevent executing any scripts added to the page via parser-based DOM APIs". It's not entirely clear to me how we'd best define the contours of that, but let's sketch it out and then bring it to WebAppSec for discussion.
 

Comment 1 by mkwst@chromium.org, Feb 17 2017

aaj@ is totally going to file a bug against WebAppSec with what he wants: https://codereview.chromium.org/2657623005 is relevant.

Comment 3 by est...@chromium.org, Nov 10 2017

Labels: Hotlist-EnamelAndFriendsFixIt

Comment 4 by est...@chromium.org, Feb 18 2018

Labels: -Hotlist-EnamelAndFriendsFixIt

Sign in to add a comment